Dual Security Processor ATM Cash Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated Teller Machines (ATMs) face vulnerabilities in cash handling operations due to exposure of cryptographic techniques and keys during authentication, maintenance, and remote software loading, making them susceptible to criminal compromise.
Innovation Solution
A valuable media handling device with dual security processors, where a master processor outside the safe controls and validates operations via an internal bus connection with a slave processor inside the safe, reducing exposure and enhancing cryptographic security through real-time encryption and tamper-responsive key erasure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single security processor is used in the recycler component, then authentication operations can be performed, but cryptographic techniques and keys are exposed during authentication, maintenance, and remote software loading
Solution Approach 1:
The security processor is divided into two separate entities: a first security processor located outside the safe and a second security processor located inside the safe. This segmentation isolates the cryptographic keys within the second processor, preventing exposure during maintenance and remote software loading operations performed on the first processor.
Solution Approach 2:
The cryptographic keys and sensitive authentication data are extracted from the first security processor and stored exclusively in the second security processor inside the safe. This extraction ensures that keys are not exposed during routine maintenance or remote software updates of the first processor.
2Reliability
If independent authentication is performed by each component, then security validation is thorough, but the exposure of cryptographic keys increases during each authentication operation
Solution Approach 1:
The first security processor acts as an intermediary that handles authentication operations without containing the actual cryptographic keys. It communicates with the second security processor inside the safe, which holds the keys. This intermediary arrangement allows authentication to proceed while keeping keys isolated and protected.
3Ease of operation
If cryptographic keys are stored in the recycler component, then authentication can be performed, but keys are exposed during maintenance and remote software loading
Solution Approach 1:
The system is segmented into two security processors with distinct roles: the first processor outside the safe handles operational authentication tasks, while the second processor inside the safe securely stores cryptographic keys. This segmentation allows maintenance and remote software loading on the first processor without exposing the keys in the second processor.
Data Source
AI summary
A valuable media handling device is presented having two security processors. A top box for an escrow module of the valuable media handling device includes a master security processor. The master security processor is connected to a slave security processed located within a safe of the valuable media handling device via an internal bus connection. The master security processor controls and validates operations and modules of the valuable media handling device and the slave security processor controls and validates operations that access the safe for depositing or dispensing valuable media from the safe.


